🔧This article may rely heavily on AI/LLM-generated text. Claims and citations should be verified.
#appeals channel in either Zulip or Discord to request removal.LLM-generated text may include hallucinated citations, inaccurate claims, or statements which are correct, but are supported by the wrong citation. AI text often also does not follow the editorial guidelines and generally contain prose of poor quality. You can help by replacing weak citations with verifiable sources, auditing the article for inaccurate content, and rewriting passages to comply with the guidelines.
Alibaba Group is a multinational technology company founded in 1999 that operates a broad ecosystem of e-commerce, cloud computing, digital payments, logistics, and technology services. The company is one of the world's largest e-commerce companies, best known for its marketplaces: Alibaba.com and AliExpress. Its business ecosystem also includes major platforms like Taobao and Tmall. Over the years, the company's platforms have faced a wide range of criticism, such as: data privacy concerns, cybersecurity concerns, counterfeit goods, product quality, intellectual property disputes, and customer service disputes.
AliExpress
AliExpress is one of Alibaba Group's international and consumer-facing e-commerce marketplaces. It was founded in 2010. AliExpress connects consumers worldwide with third-party sellers, offering products in a wide range of categories including electronics, apparel, household goods, accessories, and other consumer products.
Since AliExpress serves consumers directly across international borders, it represents the portion of Alibaba Group's ecosystem where issues involving product safety, seller accountability, consumer disputes, and personal data transparency have the greatest direct impact on consumers.
Consumer impact summary
AliExpress' marketplace model creates significant challenges. The platform hosts a large number of independent sellers operating across different jurisdictions, making consistent enforcement, product verification, and accountability more difficult. Consumers may face challenges related to product authenticity, product safety, dispute resolution, and understanding how their personal data is processed throughout a complex network of third-party providers.
AliExpress demonstrates some willingness to engage with consumer concerns and provide explanations of its policies. However, recurring concerns regarding marketplace accountability and transparency prevent it from being considered a strong consumer protection model.
Incidents
Counterfeit and unsafe goods
Consumers and regulators have repeatedly criticized AliExpress for allowing product listings of fake branded goods and potentially unsafe products on the platform.[1]
Data privacy concerns
AliExpress has faced criticism over how much user data it collects, how transparent it is about sharing that data, and the cybersecurity risks associated with third-party sellers. No major confirmed AliExpress data breach has been widely reported.[2]
Independent Review and Investigation Into AliExpress Privacy Transparency
Background
To better understand how personal information is handled after it is shared with one of Alibaba Group's platforms, AliExpress, an independent inquiry was conducted directly with the AliExpress Data Protection Team regarding transparency with privacy and the handling of user data. The objective was not to challenge AliExpress' privacy policy, but to determine how the policy operates in practice and to clarify ambiguous language that many consumers encounter when attempting to understand how their data is processed.
Method
The inquiry focused on four principal questions:
- What are the "purposes explicitly outlined" in AliExpress' data processing agreements?
- How is the "period of service" defined when determining data retention?
- Under what circumstances may third parties retain personal information after the service period ends?
- What contractual restrictions prevent third parties from using customer data for their own independent purposes?
The questions were generated based on the terms in AliExpress' privacy policy and ongoing communication with the AliExpress Data Protection Team. Over multiple correspondences, AliExpress expanded upon its initial policy-level responses and provided practical examples illustrating how these concepted are intended to function for consumers' data.
Key Findings
Limits on third-party use
AliExpress stated:
"The permitted purposes are strictly tied to the service function."
...and provided the following example:
"If you purchase an item, the permitted purpose for sharing your address with a logistics provider is solely to deliver that specific package. It does not permit the logistics provider to use your address for their own purposes."
This example provided by the AliExpress Data Protection Team represents the clearest form of operational disclosure received during the inquiry. Instead of relying solely on contractual language, AliExpress confirmed that "logistics Provider[s]" are contractually limited to performing the specific services for which user data was disclosed. This answers one of the largest fears consumers may have when doing business with a company: "once my data leaves AliExpress, can another company just do whatever it wants with it?"
Data Processing Agreements
AliExpress confirmed that it maintains Data Processing Agreements with third parties. According to AliExpress:
"Third-party processors are legally restricted to using personal data solely for the purposes explicitly outlined in the agreements."
Also:
"Third parties are prohibited from utilizing personal data shared by AliExpress for any purposes beyond the scope of contracted services."
This provides consumers and users of the AliExpress platform with assurance that and third parties are contractually prohibited from repurposing customer information for unrelated commercial means.
Data retention
AliExpress describes:
"Data retention periods should be strictly limited to the period of service provided to AliExpress."
When pressed for clarification, AliExpress further explained that, after the "service period" ends:
"Service providers are obligated to immediately delete or securely destroy all such personal data... unless a specific legal obligation mandates further retention."
This is one of the strongest processor-deletion commitments made during the inquiry.
Exceptions to deletion
AliExpress acknowledged that retention beyond the service period may occur:
"Retention beyond the service period occurs only under strict legal mandates (e.g. tax compliance) or security needs."
This was the first communication provided by AliExpress that introduced "security needs" as an independent basis for post-service retention.
Transparency Assessment
The correspondence with the AliExpress Data Protection Team evolved a great deal during the inquiry. The initial responses provided by AliExpress consisted primarily of policy language. After pressing multiple times for clarification on ambiguous responses, AliExpress supplemented the previous responses with practical examples demonstrating how contractual purpose limitations and retention principles operate.
Several operational concepts, however, remain undefined--even after repeated requests were made to the AliExpress Data Protection Team. These include:
- the operational meaning of "security needs,"
- which categories of personal data may be retained under that exception,
- how long data retained for security purposes may remain stored,
- the operational meaning of "transaction lifecycle or account status,"
- whether different account states (active, inactive, suspended, deleted) affect retention, and
- whether any categories of processors perform analytics, fraud modeling, or security improvement beyond direct service delivery.
Instead of providing additional clarification on these requests, AliExpress concluded the correspondence by stating:
"We believe the previous illustrations have addressed the points you raised... we consider our responses on this matter to be complete."
This position was acknowledged. However, the undefined questions and AliExpress' decision not to provide further clarification are documented here as part of this inquiry on transparency.
Although AliExpress provided additional explanations beyond its published privacy policy, those explanations introduced new operational concepts that prompted further questions about how user data is actually handled in practice. Rather than clarifying those additional issues, AliExpress declined to provide further detail and concluded the correspondence. Consequently, the inquiry expanded the understanding of AliExpress' stated practices, but simultaneously exposed additional areas where operational transparency remained undefined.
Consumer Impact
This inquiry demonstrates that AliExpress is willing to explain several important privacy concepts beyond the wording of its public privacy policy. At the same time, this inquiry illustrates a common challenge of broad operational concepts. Examples from this inquiry include: "security needs" remaining undefined and leaving consumers without a clear understanding of when data may continue to be retained after normal service has concluded.
Additional specificity would better align with the transparency principles reflected in the GDPR, which encourages information provided to data subjects to be transparent, intelligible, and meaningful. Even though the inquiry produced a great deal more information than initially available through AliExpress' published privacy materials and early communications, there are several operational questions that remain unanswered at the conclusion of this inquiry since AliExpress indicated it considered the matter closed on their end.
References
- ↑ Foo, Yun Chee (2026-07-20). "AliExpress hit with $629 million EU fine over sales of illegal, counterfeit products". Reuters. Retrieved 2026-07-20.
{{cite news}}: CS1 maint: url-status (link) - ↑ "Commission accepts commitments offered by AliExpress under the Digital Services Act and takes further action on illegal products". European Commission. 2025-06-17. Archived from the original on 2026-01-12. Retrieved 2026-07-20.